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RESPONSE TO AMENDMENTS 

1. This action is in response to amendments received 2 March 2005. 
REMARKS /RESPONSE TO ARGUMENTS 

2. Applicants amended claims 6-9 and 15-18 to overcome rejections under 35 U.S.C. 112, 
second paragraph as being indefinite. Examiner has considered fully the amendments, and 
they have overcome said rejections. Examiner withdraws rejections under 35 U.S.C. 112 second 
paragraph from these claims. 

3. Applicants' arguments to the rejections under 35 U.S.C. 102 have been fully considered 
but are not persuasive. With regard to Applicants' argument that Levergood discloses two 
communication servers as opposed to an application communicating with an application server, 
Examiner respectfully disagrees. While Applicants argue that the present invention recites an 
application and application server, the present invention does recite communication with the 
application server ("sending the user information page../ 7 , "returning a filled out user 
information page. . ."), and the limitations recited in the claims do not distinguish it as to 
preclude communication between two servers. It should be noted that the invention as claimed 
- as well as the disclosure of Levergood - pertains to a traditional client/ server arrangement in 
which one computer provides a service (server) and the other requests and receives that service 
(client). In this respect Levergood is equivalent to and anticipates the instant invention. That 
Levergood labels both computers "server" does not detract from the fact that one provides 
authentication as an application (server role), and one is the computer accessing the 
authentication application (client role). Furthermore, the paragraph from Levergood that 
Applicants quote (column 5, lines 42-52) clearly states that the content server only acts as a 
proxy for the actual user to the authentication server ("to redirect the user's initial request to an 
authentication server", "the result of the process is an SID provided from the authentication 
server to the client"). Thus, even if it were true that the communication takes place between two 
servers, the content server is clearly acting in the client role of the client/ server arrangement 
and thus anticipates the application in communication with the application server of the instant 
invention. 
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4. With regard to Applicants' argument regarding the process Levergood uses when a user 
does not have an account, Examiner respectfully disagrees. The authentication server of 
Levergood inherently runs a security application because the act of authentication is a security 
application. Part of that application is disclosed as opening - the equivalent of "bootstrapping" 
- a new user account. It is based on user information solicited by a user information request 
page formed by an application (see column 6, line 58 - column 7, line 14). The user account is 
based upon security data extracted from the "real-time on-line registration". Note the password 
(figure 5) v , credit information (column 7, line 7) contained in the user information request page. 
Thus Levergood's authentication server handling the opening of a new account for the user is a 
disclosure of an application server bootstrapping a user account in a user database based upon 
security data extracted from a filed-out user information request page with the user inf omration 
request page formed by an application. 

CLAIM REJECTIONS - 35 U.S.C 102 

5. Regarding claims 1-2, 10-11, and 19, Levergood, et al. disclose, in a browser/ server 
environment, a server requesting credentials from a user " which causes the client browser to 
prompt the user for credentials 7 ', requiring the user to fill out and return information and 
security data, (see column 6, lines 44-57; Figure 5). This meets the limitations claimed of 
forming and sending a user information request page. This also meets the limitations of 
returning the user information request page through a server target on the application server, 
and of forwarding it to the application on the application server. 

Levergood, et al. disclose the use of information and security data provided by the user to 
initiate a new user account in the database (see column 3, lines 28-38; column 6, line 58 - column 
7, line 14), which meets the limitation of bootstrapping a user account in the user database by 
the application server based upon the extracted security data. 
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6. Regarding claims 3 and 12, Levergood, et al. disclose that "the authentication server 
checks to see if the user qualifies for a new account 7 ' (see column 6, line 67 - column 7, line 3), 
meeting the limitation of making available a set of user security requirements. 

7. Regarding claims 4-5 and 13-14, Levergood, et al. disclose a success target and a failure 
target to provide respective destinations for the bootstrap attempt. These targets are disclosed 
as URLs capable of being shown in a browser (see Figure 2B; column 7, lines 51-67). 

8. Regarding claims 6-9 and 15-18, Levergood, et al. disclose merging the set of security 
registration requirements and user profile data requirements to collect corresponding user 
profile data from the user. They are forwarded back, extracted, and stored in a user profile 
database (see column 6, line 58 - column 7, line 14). 

CONCLUSION 

9. Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Daniel M. Ungar whose telephone number is 571.272.7960. The 
examiner can normally be reached on 8:30 - 6:00 Monday - Thursday, Alt. Fridays. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Gilberto Barron can be reached on 571.272.3799. The fax phone number for the 
organization where this application or proceeding is assigned is 703-872-9306. 

Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private 
PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). 



Art Unit 2132 
Daniel M. Ungar 



GILBERTO BARRON * 
SUPERVISORY PATENT EXAMINER 
TECHNOLOGY CENTER 2100 



